Chapter 5, Part I Risk Assessment: Internal Control Evaluation

0.0(0)
studied byStudied by 0 people
full-widthCall with Kai
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/34

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

35 Terms

1
New cards

Internal controls are designed to provide reasonable assurance that

Material errors or fraud will be prevented, or detected and corrected, within a timely period by employees in the course of performing their assigned duties.

2
New cards

When obtaining an understanding of an entity’s internal control, an auditor should concentrate on their substance rather than their form because

 Management may establish appropriate controls but not enforce compliance with them.

3
New cards

In obtaining an understanding of internal control in a financial statement audit, an auditor is not obligated to

Search for significant deficiencies in the operation of internal control.

4
New cards

Less Reliance on Internal Control:

higher control risk; higher RMM; ______ detection risk

lower

5
New cards

More Reliance on Internal Control;

lower control risk; lower RMM; ______ detection risk

higher _

6
New cards

What is the purpose of adequate internal controls?

To detect and prevent material errors or fraud in financial reporting.

7
New cards

Define internal control.

A process effected by an entity’s board, management, and personnel to provide reasonable assurance of achieving objectives in reporting reliability, operational effectiveness, and legal compliance.

8
New cards

Who retains authority over decisions and reviews management’s assignments?

The Board of Directors.

9
New cards

Who establishes directives, guidance, and controls?


Senior Management.

10
New cards

What is the role of outsourced service providers in internal control?


Follow management’s authority and responsibility.

11
New cards

What is the purpose of ICFR?


Reduce risk of material errors/fraud and support accurate reporting.

12
New cards

What level of assurance do internal controls provide?


Reasonable assurance (not foolproof).

13
New cards

What are three limitations of internal control?


Human error, management override, and collusion (plus cost-benefit).

14
New cards

What is management’s responsibility for internal controls?


Establish, maintain, assess, and report on effectiveness.

15
New cards

What is the auditor’s responsibility for internal controls? ( what is their job there)


Audit and issue an opinion on ICFR effectiveness.

16
New cards

What are the five COSO components of internal control?


Control Environment, Risk Assessment, Control Activities, Information & Communication, Monitoring.

17
New cards

What is the foundation for all other internal control components?


Control Environment.

18
New cards

Deficiencies in the control environment are often linked to what?


Financial frauds.

19
New cards

What is risk in internal control?


The chance an event hurts organizational objectives.

20
New cards

What are control activities?


Policies and procedures to ensure management’s directives are met.

21
New cards

What are the two types of controls?


Preventive and detective.

22
New cards

What four functions are often segregated in duties?


Authorization, recording, custody, reconciliation.

23
New cards

What is information and communication in internal control?


Identifying, capturing, and sharing timely, relevant info.

24
New cards

What is monitoring in internal control?


Ongoing or separate evaluations of control performance.

25
New cards

What is the role of the audit committee?


Oversight, buffer between auditors and management, ensure independence.

26
New cards

Who serves on the audit committee?


3–6 outside board members, all financially literate, one expert

27
New cards

What are the three phases of internal control evaluation?


Understand/document, assess control risk, test controls.

28
New cards

What are entity-level controls?


Broad controls affecting the whole system (like monitoring or risk assessment).

29
New cards

What are transaction-level controls?


Controls over specific transactions, balances, or disclosures.

30
New cards

What is a design deficiency?


A missing or poorly designed control.

31
New cards

What is an operating deficiency?


A proper control not applied correctly or consistently.

32
New cards

What is a material weakness?


A likely chance a material misstatement won’t be prevented or detected timely.

33
New cards

What is a significant deficiency?


Less severe than a material weakness but still needs governance attention.

34
New cards

What does an unqualified opinion on ICFR mean?


Internal control is effective with no material weaknesses. (good)

35
New cards

What is an example of an internal risk? (think blue chart)


Management changes, poor business model, or IT changes.